|
#11
|
|||
|
|||
I've tried with decoder but returned many _obfuscate_
|
#12
|
||||
|
||||
did you install all dependencies ?
|
#13
|
|||
|
|||
Find out what needs to decode _obfuscate_xyiNieq6 = _obfuscate_YxcKFW9wHTcLamJ1( $_obfuscate_xyiNieq6 |
#14
|
|||
|
|||
I've tried decoding this file that uses the latest ioncube loader:
It says it needs the latest ioncube loader. Last edited by joeroberts; 5th December 2011 at 10:43. |
#15
|
|||
|
|||
Quote:
software decoder Zend Guard 4 tank |
#16
|
|||
|
|||
Is there anyway possible to decode zendguard 4 files?
|
#17
|
|||
|
|||
Code:
@echo off pushd "%~dp0" IF EXIST "%1" GOTO DECODE_INDIVIDUAL :DECODE_MULTIPLE xcopy /s /c /d /e /h /i /r /y "%cd%\_decode" "%cd%\_decoded_rm\" "%cd%\bin\nws\opdump.exe" "%1" dir %cd%\_decoded_rm\*.php /A:-D /B /O:N /S >> %cd%\filelist_rm.txt dir %cd%\_decoded_rm\*.php5 /A:-D /B /O:N /S >> %cd%\filelist_rm.txt dir %cd%\_decoded_rm\*.php4 /A:-D /B /O:N /S >> %cd%\filelist_rm.txt @echo on for /F %%e in (%cd%\filelist_rm.txt) do ( copy "%%e" "%cd%\bin\rm\file.php" && "%cd%\bin\rm\php.exe" "%cd%\bin\rm\file.php" && move "%cd%\bin\rm\main*.log" "%%e" && del "%cd%\bin\rm\file.php") del /Q "%cd%\filelist_rm.txt" GOTO DECODE_END :DECODE_INDIVIDUAL @echo on "%cd%\bin\rm\php.exe" "%1" && move "%cd%\bin\rm\main*.log" "%1.rm.txt" :DECODE_END AVG Free - Clean ArcaVir - Clean Avast 5 - Clean Avast - Clean AntiVir (Avira) - Clean BitDefender - Clean VirusBuster Internet Security - Clean Clam Antivirus - Clean COMODO Internet Security - Clean Dr.Web - Trojan.PWS.Siggen.25968\r eTrust-Vet - Clean F-PROT Antivirus - Clean F-Secure Internet Security - Clean G Data - Clean IKARUS Security - Trojan-Dropper.Small Kaspersky Antivirus - Clean McAfee - Clean MS Security Essentials - Clean ESET NOD32 - Trojan.Win32/PSW.Fignotok.K Norman - Clean Norton Antivirus - Clean Panda Security - Clean A-Squared - Trojan-Dropper.Small!IK Quick Heal Antivirus - Clean Rising Antivirus - Clean Solo Antivirus - Clean Sophos - Clean Trend Micro Internet Security - Clean VBA32 Antivirus - Clean Vexira Antivirus - Clean Webroot Internet Security - Clean Zoner AntiVirus - INFECTED [BackDoor.Generic12.DHJ] Ad-Aware - Clean AhnLab V3 Internet Security - Clean BullGuard - Clean [Info] File: opdump.exe Size: 2126027 bytes MD5: da7b998384e4bda50ad6af1142b40fb5 Rate: 5 de 35 (14%) mozsqlite3.dll and mozcrt19.dll = stealer this release equal to DeZender.DeIoncuber.06.09.2011 but infected Last edited by shimpei; 5th December 2011 at 23:56. |
#18
|
|||
|
|||
Two sample files are Look if decoder If you put it software Bump: file http://www.uploadmb.com/dw.php?id=1323620959 Bump: Quote:
http://niryazd.com/up/download/38/when.php.html Last edited by joeroberts; 6th December 2011 at 17:30. |
#19
|
|||
|
|||
Sorry, i didn't saw the second download link :-(
Bump: i made some tests and i have errors in every decoded files : PHP Code:
here is two files for tests. Last edited by brazeroo; 10th January 2012 at 23:43. |
The Following User Says Thank You to brazeroo For This Useful Post: | ||
zhanyuanhong (2nd May 2017)
|
#20
|
||||
|
||||
thanks
thanks u help me with this articles, its working!
|
Tags |
deioncuber , dezender , dezenderdeioncuber |
|
|